Shopify, Sidekick and Shopify Magic

Research date: 4 October 2026
Edition: First Shopify baseline report
Method: Review of Shopify's public documentation. No signed-in business account was inspected and no controls were tested in a live store.

Summary

Shopify’s AI can assist with store management, customer replies and selling through external AI channels. Some functions require no separate AI purchase.

  • By default: AI suggested replies in Inbox are documented as on for eligible stores. The report does not establish that autonomous replies, Sidekick Pulse or every other AI feature is on by default.
  • Beyond the default: Content and image creation, reports, customer segments, proactive recommendations, customer-facing Inbox agents, order-edit proposals, app creation and supported financial or app tasks.
  • Outside Shopify: Inbox agents can use web results for product reviews or social proof. AI shopping channels can receive product details and, for direct checkout, the customer information needed for that order. Connected AI providers and installed apps introduce separate access routes.
  • Business exposure and learning: Generated apps can read and change store information through the Admin API. Sidekick’s foundation-model training commitment does not settle every improvement use. Shopify explicitly describes using Inbox customer conversations to improve its agent. Network Intelligence combines information for enhanced services, without giving other merchants the business’s customer data.

The main exposure: AI can progress from suggesting text to changing store records, supporting transactions and answering customers. External sales channels have narrower access than a management app; they should not be treated as equivalent.

Business finding

Shopify is a commerce platform. Its AI is spread across store administration, customer conversations, recommendations and sales channels. A business can stop selected uses, remove external connections and restrict permissions. This review did not establish a single control that disables all Shopify AI.

Sidekick is only part of the picture. Some assistance appears inside ordinary editing screens. AI shopping channels can be enrolled automatically, while a separate customer-data setting supports services used across Shopify's network. [1][2][3]

The business needs to assess what information each route uses, what changes it can make and what other functions depend on keeping that route active.

Where is AI operating?

Sidekick and built-in assistance: Sidekick can help with content, reports, store tasks and app creation. AI also appears in product categories, customer-segment descriptions, spending projections, images, themes and app-review summaries. Many features are available without an additional AI purchase. Shopify's current Help Center groups these under AI-powered tools; older materials use Shopify Magic. [1]

Proactive recommendations: Sidekick Pulse can research the store and present suggested tasks without the business starting a chat. It requires recent sales activity, owner or administrator access and Shopify Network Intelligence. [4]

Customer conversations: Inbox has separate AI suggested replies for staff and an optional agent that answers customers directly. Suggested replies are on by default for eligible stores. Turning off one does not establish that the other is off. [5][6]

AI shopping channels: Agentic storefronts let customers discover products and, where supported, buy through AI channels. These are different from an external assistant given permission to manage the store. [7][8]

Network-based services: Shopify Network Intelligence uses customer information alongside information from other merchants and Shopify to produce insights for Enhanced Services. Shopify says other merchants do not receive the business's customer data. This is a separate use from a Sidekick conversation. [3]

Who controls it?

The business controls staff permissions, app installations and store settings. Shopify states that Sidekick uses the logged-in user's permissions. Review those permissions before relying on them as the limit on AI access. [9]

Generated apps require the App development → Develop permission. After installation, their permissions and removal need separate review. [10]

For official external AI integrations, the business approves both the tool's requested access and the user's permissions. Read access allows viewing; write access allows changes. A user cannot grant the tool capabilities beyond that user's own permissions. [11]

Name the person responsible for each route, including customer chat, product distribution and any apps or workflows created with AI. For an agency-managed store, record who in the business can require access to be removed.

What can the business switch off?

Sidekick and its memory

This review did not find a documented store-wide Sidekick off switch. Not opening a conversation avoids that deliberate use, but does not establish that proactive recommendations or other built-in AI processing have stopped.

Within a Sidekick conversation, turn off Memory using the desktop toggle or the mobile Plus → Memory control. Shopify says this prevents use of saved memory and recent admin activity in that conversation and prevents new memory being saved. It is a conversation-level control. [12]

Inbox assistance and automated chat

For staff suggestions, use Shopify Inbox → Settings → Message preferences → Automatically generate a reply → Off → Save. [5]

For the customer-facing agent, use Shopify admin → Sales channels → Inbox → Inbox agent, and turn it off. Shopify says the change takes effect immediately for new conversations. Test existing conversations separately and ensure staff can receive requests. [6]

AI sales channels

Use Shopify admin → Sales channels → Agentic. Turn off Allow Shopify to manage for me, then manage Shopify Catalog access, Auto enroll new storefronts and relevant channel checkout settings. Save the changes. Catalog withdrawal can take up to seven days. Turning managed settings back on reactivates settings, including direct checkout. [2]

This stops the covered distribution route, not every way an AI can discover a public product page. Shop is separately controlled and does not offer the same Catalog off switch. [2][7]

Network Intelligence

Use Settings → Customer privacy → Shopify Network Intelligence → Disable. Review the removal list, type UNINSTALL, then click Uninstall. This affects other functions immediately; assess the consequences before changing it. [13]

External AI connections and generated apps

Uninstall an official external AI integration from Shopify admin to revoke its access. Shopify says reducing an approved access level also requires uninstalling and reinstalling with less access. [11]

An app created with Sidekick is an installed app in its own right. Review or uninstall it separately; ending the creation conversation is not evidence that the installed app has stopped. [10]

What information and actions can the business restrict?

Route What to review
Sidekick Staff permissions and the store records needed for the task. [9]
Sidekick memory Preferences, conversations and recent admin activity. [12]
Inbox agent Catalog, policies, Knowledge Base content, published pages and permitted customer context. [14]
AI sales channels Product information and information supplied for orders placed through direct checkout. [7]
External AI integrations Read/write access, user permissions and the receiving provider's terms. [11][15]
Generated apps Installed permissions and the records the app can change. [10]

Sidekick can propose edits to orders and draft orders. Shopify's guidance describes review before Update order or Save. It can also help prepare Shopify Balance transfers and use supported installed apps after approval for the current conversation. Review the actual task's confirmation steps; do not assume every capability is merely a writing suggestion. [16]

Generated apps can use orders, products, customers, discounts, content and analytics through the Admin API. Shopify warns they can change customer-facing data and should be tested before installation. Their operation deserves its own assessment. [10]

The Inbox agent uses store sources and can use web results for product-related reviews or social proof. Its order lookup requires customer sign-in. The staff-chat sign-in setting does not itself govern the agent's access to account information. Check authentication and customer-specific behaviour separately. [14]

For AI sales channels, Shopify documents sharing product titles, descriptions, images, prices and availability. Direct-checkout channels can also receive the customer's contact and delivery details for that order. It says these channels do not receive the general customer database or full order history through this route. [7]

External management tools have different limits. Shopify documents restrictions on live-theme publishing and paid-order actions for its covered integrations. Those limits should not be assumed to apply to every independently installed app. [15]

Can the business refuse use of its information for training?

Sidekick: Shopify's published enterprise explanation says store data is not used to train foundation models or shared with other merchants. This is a provider commitment, not a control tested in this report. It does not establish the treatment of every prompt, feedback item, extension response or service-improvement use. [9]

Inbox agent: Shopify explicitly says customer chat communications are processed to generate responses and improve the agent's quality over time. This review did not establish a separate setting that refuses improvement use while retaining the agent. Ask Shopify to confirm the scope before treating the Sidekick statement as covering customer chat. [6]

Network Intelligence: Disabling it stops additional customer information from the store being used going forward to power Enhanced Services. This is not documented as a universal refusal of AI training or a promise to remove previous learning. [13]

External tools: Information passed to a connected AI provider is governed by that provider's terms and privacy policy. Shopify says it does not control that provider's subsequent use or retention. Review training and improvement settings with the provider itself. [15]

Memory and deletion: Turning off Sidekick memory is different from refusing training. Deleting a conversation removes it from chat history and memory of previous interactions, while saved preferences remain. Shopify also lets users ask Sidekick to forget specific details. These instructions do not establish deletion from every backup or processing record. [12]

Customer advertising opt-outs are another distinct control. They should not be described as switching off all business AI.

How can the business check that its choices worked?

The following are proposed business checks, not tests completed for this report:

  1. Record enabled tools, channels, installed apps, staff permissions, settings and change dates.
  2. Reopen settings after saving and check each store separately.
  3. Use harmless test records with staff accounts having different permissions. Confirm restricted information cannot be retrieved or changed.
  4. Test Inbox staff suggestions and the customer-facing agent separately. Check new and existing conversations and whether customers can reach staff.
  5. Test memory-off behaviour and review saved preferences separately from conversation history.
  6. Review each AI-created app and workflow. Confirm who can run it, what it changes and how to stop it.
  7. After revoking an external integration, test that it cannot make a fresh read or edit. Ask the provider separately about previously received information.
  8. Record Catalog withdrawal time and reassess after the documented seven-day window. Do not treat continued discovery through web search as proof that the Catalog control failed.

Keep evidence of settings and observable results. A screenshot or successful test cannot independently establish all provider-side processing, training compliance or deletion.

What does the business lose, retain or need to replace?

Avoiding content and reporting assistance means staff may need to write descriptions, prepare campaigns, inspect reports and maintain the store manually. Turning off automated Inbox chat requires staff coverage and a usable contact route.

Network Intelligence withdrawal is a substantial operational choice. Shopify lists affected functions including managed payment methods, Shop, Audiences, Collabs, Collective, Messaging, Product Network and Search & Discovery. Re-enabling the setting does not restore uninstalled apps automatically; they require installation and setup again. [13]

Removing AI-channel distribution may reduce product discovery or change where checkout happens. Broader product hiding has wider consequences: Unlisted products are removed from Shopify Catalog, internet search, sitemaps and Shopify-powered collection pages, store search and recommendations. A direct product URL still works. This is not a narrow AI-only exclusion. [17]

For retained AI, measure useful results against checking time, corrections, customer outcomes and app or provider costs. Potential benefits include faster content preparation, easier analysis and additional product discovery. This report did not independently measure sales gains or productivity savings.

Control assessment

Requirement Finding
Disable Sidekick store-wide Not established in the documentation reviewed.
Stop Sidekick memory Conversation-level control documented; preferences and history require separate review.
Stop Inbox suggestions or automated chat Separate controls documented.
Stop AI-channel distribution Controls exist, with delay, Shop differences and other discovery routes.
Restrict external management tools Authorisation and uninstall routes documented.
Stop Network Intelligence data use Forward-looking control, with significant loss of dependent functions.
Refuse all training and improvement uses Not established across all products and routes.
Verify complete absence of AI processing Not established from published information.

Sources and scope

Official Shopify sources checked on 4 October 2026:

  1. AI-powered tools
  2. Managing agentic storefronts
  3. Network Intelligence: terms-update FAQ
  4. Sidekick Pulse
  5. AI-generated suggested replies in Inbox
  6. Assigning your Inbox agent to conversations
  7. Agentic storefront data sharing and privacy
  8. Managing your store with third-party AI tools
  9. Shopify's Sidekick explanation: permissions and foundation-model training
  10. Generating apps with Sidekick
  11. Authorizing AI tool access
  12. Sidekick memory and personalization
  13. Customer privacy settings and Network Intelligence removal
  14. Inbox agent persona, data sources and safety limits
  15. Considerations for third-party AI tools
  16. Getting help and guidance from Sidekick
  17. Product hiding and search visibility

This report covers principal admin AI, Sidekick, Inbox, AI shopping channels, Network Intelligence and official external-management connections. It is not a complete audit of every Shopify app, payment-risk system, recommendation model, Tinker tool or custom integration. Availability depends on plan, eligibility and rollout. Shopify's published statements are distinguished from independently verified behaviour.

Unresolved: store-wide Sidekick control; complete training/improvement treatment of prompts and extension information; existing conversations after agent withdrawal; retention beyond visible history; stopping actions already passed to another system; geographic processing for each route; independent verification of provider commitments.

Changes since previous Shopify report: None. This establishes the first Shopify baseline for subsequent monthly research.